cat-sis2go-utils is a dependency-confusion package published against the SIS2GO namespace, with versions inflated to 99.0.0 and 99.1.0. It ships no library code (index.js is an 87-byte stub), and package.json declares both preinstall and postinstall running node scripts/run.js, so the payload executes twice during npm install before any application code. The script resolves a DNS canary and POSTs to a webhook.site collector; 99.1.0 additionally sends os.userInfo().username and os.hostname(). The author labels this a PoC, but the beacon fires on any install that resolves the package and exfiltrates a username usable for follow-on attacks, and dependency-confusion packages require incident response even when trivial.
-= Per source details. Do not edit below this line.=-
Package cat-sis2go-utils@99.0.0 declares both preinstall and postinstall lifecycle hooks in package.json that execute scripts/run.js on every npm install. The script unconditionally issues a DNS lookup against d22d92dc-84e5-4b58-8cd6-75bf1ac452c7.dnshook.site and POSTs a JSON beacon containing the installer's hostname and process context to https://webhook.site/d22d92dc-84e5-4b58-8cd6-75bf1ac452c7. The package description self-identifies as a dependency-confusion PoC, and the 99.0.0 version is consistent with a resolution-winning squat targeting an internal package name. Installing the package results in arbitrary code execution on the installer host and fingerprints the machine to third-party out-of-band collectors under the operator's control.
{
"iocs": {
"domains": [
"d22d92dc-84e5-4b58-8cd6-75bf1ac452c7.dnshook.site"
],
"files": [
{
"digests": {
"sha256": "0897440200959313ca1e8735d8d1524f70a0bddcde66778ecd46c0bb4981981f"
},
"note": "Present in versions 99.0.0 and 99.1.0.",
"paths": [
"index.js"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "91b460b9612ce51d74cb187bcf1793bd115255b117e5ca5858075c3a90b6b2b9"
},
"note": "Present in version 99.0.0.",
"paths": [
"package.json"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "b0ccdc7aaba664b0b4da3f317d06789d4cda2473f50c37a1c13264389130d6d7"
},
"note": "Present in version 99.0.0.",
"paths": [
"scripts/run.js"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "0e3e6be9b193ff4b3e6bd60bc0bfe1d97b9f1c2d73d8fa2d731597b00b8501c1"
},
"note": "Present in version 99.1.0.",
"paths": [
"package.json"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "0b598419ad8ba34a16ac19961d91208266d100dfed2598d298fbf9d5cb7eea2b"
},
"note": "Present in version 99.1.0.",
"paths": [
"scripts/run.js"
],
"source": "PACKAGE_ARCHIVE"
}
],
"urls": [
"https://webhook.site/d22d92dc-84e5-4b58-8cd6-75bf1ac452c7"
]
},
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-019843",
"import_time": "2026-09-09T05:40:09.19538336Z",
"modified_time": "2026-09-09T05:33:44Z",
"sha256": "205b59e55b3e3474f6b5de7471c11e7095e019a9f1e682083b34eeb7dddd5c3f",
"source": "amazon-inspector",
"versions": [
"99.1.0"
]
},
{
"id": "IN-MAL-2026-019845",
"import_time": "2026-09-09T05:40:09.252208812Z",
"modified_time": "2026-09-09T05:34:00Z",
"sha256": "ad357542f3dd0e1b598ef36d440b1868ac28c6889226864bf799b2f7b6bf5e91",
"source": "amazon-inspector",
"versions": [
"99.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "scripts/run.js",
"sha256": "0b598419ad8ba34a16ac19961d91208266d100dfed2598d298fbf9d5cb7eea2b",
"tlsh": "952103e648f581281ef342c0574bec5aa273da067546ee9076ac03321fc59fc9a739f8"
}
],
"package_integrity": [
{
"filename": "cat-sis2go-utils-99.1.0.tgz",
"hashes": {
"sha1": "49e87faf015f6773e543b29044c7ee396b20c85f",
"sha512_sri": "sha512-wx8JSI0n1stzrdeP3eUD9piuGQKVMbrB4/ZV/Ez1IaNUT+4EBXSmejvY64wx7xd9dQ43x60XN4i3msVUW3dr6A=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cat-sis2go-utils/MAL-2026-16071.json"